feat(billing): reconcile Stripe state from current provider authority - #569
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Caution Review failedAn error occurred during the review process. Please try again later. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Buyer/reliability objective
Refs #488. This stacked Draft adds the bounded orchestration boundary needed for out-of-order Stripe deliveries to trigger current provider reconciliation rather than becoming lifecycle authority themselves.
Exact current stack
develop:2dcbdc06d3a9e2f87eac42447338e7fcc523dd54;feat/stripe-entitlement-billing-status-488@6fcbaa4b85d70d7b7b98bc85e977a25624df32f1;3e95927c2b28a2b73c2b589c53fdd74a95b01d2a;Any parent, contributor-head, or protected-base movement invalidates ancestry- and head-sensitive evidence until freshly reconciled.
Implemented current-authority contract
server/stripe_billing_reconciliation.mjsnow:latest_invoice_idexists, fetches the authoritative Invoice using exact organization/Customer/Subscription/Invoice authority and appends it against the just-accepted Subscription observation;orgs.planmutation, session state, or RBAC mutation.TDD and causal hardening
25fa45155c754e54ce63a96a8a8bd43f0b6ae2e3added realistic regressions proving Subscription, Invoice/source-observation, and claim identity substitution must fail closed;7cea2f780554ccb4568bb9d9a2d56a67faac53f3wired that regression into an already-executed package-contract path so the RED evidence could not be vacuous; and3e95927c2b28a2b73c2b589c53fdd74a95b01d2aimplements the smallest root-cause fix by treating repository return values as untrusted port data and re-binding their identities before they enter the reconciliation receipt or downstream claim application.The original module-resolution RED predecessor is historical diagnostic evidence only; this PR is no longer intentionally RED.
Current exact-head evidence
Fresh repository-native workflows for exact contributor head
3e95927c2b28a2b73c2b589c53fdd74a95b01d2acurrently remain queued and therefore non-passing:32361538176;32361538188; and32361538771.There is no qualifying independent current-head approval. Queued, pending, skipped-required, cancelled, absent, neutral-required, failed, stale, predecessor, synthetic, status-only, author-only, or model-only evidence is non-passing.
Scope and merge boundary
This slice does not by itself close #488. It provides the current-provider reconciliation service boundary over the preceding authoritative Subscription/Invoice evidence and durable claim layers; operator recovery, end-to-end deployment/restart/concurrency acceptance, retention/export controls, and release evidence remain broader lifecycle work.
Remain Draft. Do not integrate independently of #568 and its prerequisite #488 stack. After the prerequisite stack reaches protected
develop, reconcile this bounded semantic delta onto the resulting live head and regenerate every then-applicable exact-head deterministic/browser/statement/branch/function/line coverage/docstring/SAST/security/dependency/supply-chain/package/provenance/migration/recovery/review gate required by live policy.